Judge intelligence by whether its provenance is understood, the underlying evidence can be distinguished from analysis, it is timely for the decision, sufficiently specific to the environment, appropriately caveated, corroborated where material and connected to an operational decision. A large feed or high confidence label is not proof of quality.
External reference
NIST guidance emphasises goals, sources, sharing rules and effective use of cyber threat information. The quality dimensions on this page are a Cybatar-authored operational method, not a NIST scoring standard.
Primary source →Operational method
Check provenance
Know the originating source, collection method where available, redistribution constraints and whether the intelligence is primary, secondary or derived analysis.
Separate observation from assessment
Keep factual observations, inferred relationships and attribution/confidence judgements distinguishable.
Check timeliness
Record creation, observation, receipt and last-reviewed times so the consumer can judge whether the intelligence is still decision-relevant.
Check environmental relevance
Relate intelligence to technologies, identities, services, geography, sector, exposures or incidents that actually affect the organisation.
Measure decision impact
Record whether the intelligence changed monitoring, hunting, remediation, incident response or risk treatment. Useful intelligence should support a traceable decision or hypothesis.
Relevant Cybatar sources
Claim boundary
The Cybatar quality method is first-party guidance. It is not an intelligence-provider rating standard, does not establish source truthfulness and cannot remove uncertainty from threat attribution.
These pages are Cybatar-authored threat-intelligence and threat-hunting guidance. NIST, OASIS and MITRE ATT&CK are external sources. References do not establish certification, endorsement, native STIX/TAXII compatibility, complete threat coverage, attribution certainty or proof that a hunt found all malicious activity.